🤖 AI Summary
Existing full-system firmware rehosting approaches struggle with custom devices due to their reliance on expert knowledge and inability to handle proprietary architectures and hardware configurations, leading to initialization and runtime failures. This work proposes the first fully automated, adaptive Linux firmware rehosting framework powered by large language models (LLMs), integrating static analysis, LLM-driven adaptive reasoning, reflective configuration synthesis, and autonomous runtime intervention to achieve end-to-end automation. Evaluated on 21 IoT firmware images spanning five distinct architectures, the approach attains a 100% network port activation rate and a 90.5% service interaction success rate, substantially outperforming current state-of-the-art methods. Furthermore, it successfully reproduces known vulnerabilities and uncovers previously unknown security flaws.
📝 Abstract
Full-system rehosting plays a critical role in the security analysis of Linux-based firmware. It matches commonly deployed firmware with sufficient background knowledge. However, for custom devices, existing approaches struggle to handle initialization and runtime obstacles in the rehosting process caused by specialized architectures and hardware-dependent configuration, which heavily rely on expert intervention. This ultimately creates fundamental bottlenecks and results in low rehosting efficiency. To address the above challenges, we propose FirmCure, the first LLM-driven full-system rehosting framework designed for autonomous and adaptive rehosting of Linux-based firmware. FirmCure develops an Adaptive Perception Inference mechanism to extract firmware structural dependencies via static analysis, followed by a Reflective Synthesis module for iterative configuration optimization, and finally an Autonomous Runtime Intervention module for real-time error remediation through runtime fault diagnosis and monitoring. We evaluated 21 IoT firmware images from 10 vendors across 5 architectures, while FirmCure achieved a 100% network port opening rate and 90.5% service interactivity, substantially outperforming state-of-the-art baselines. Our experiments confirm that FirmCure's intervention strategies generalize across heterogeneous firmware. The framework successfully reproduces known vulnerabilities and discovers new security flaws.